The tiny artifact has a README and no install hooks, keeping its operational footprint simple. The MIT declaration and non-archived repository help, but the source/package mismatch makes provenance less clear.
35%
Total Score
50
100
71
75
The artifact includes a README, but it is only 16 characters long and provides little consumer guidance. The absence of tests and a changelog is normal for published package artifacts.
The package has had only two releases, both on May 21, 2019, with none in the last seven years. This is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no update for over seven years.
The linked repository name does not match the package name and its README does not mention the package, so it may not clearly belong to this release.
Composer is used for the build, but no security scanning tooling is present. This is a modest repository-hygiene gap rather than evidence of abandonment on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.